SB20251210141 - Use of uninitialized resource in Linux kernel usb storage driver
Published: December 10, 2025 Updated: December 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use of uninitialized resource (CVE-ID: CVE-2023-53847)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to use of uninitialized resource within the alauda_get_media_status() and alauda_init_media() functions in drivers/usb/storage/alauda.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/044f4446e06bb03c52216697b14867ebc555ad3b
- https://git.kernel.org/stable/c/0d2d5282d39aed6f27dfe1ed60a5f3934ebd21cd
- https://git.kernel.org/stable/c/153c3e85873cc3e2f387169783c3a227bad9a95a
- https://git.kernel.org/stable/c/373e0ab8c4c516561493f1acf367c7ee7dc053c2
- https://git.kernel.org/stable/c/49d380bcd6cba987c6085fae6464c9c087e8d9a0
- https://git.kernel.org/stable/c/7a11d1e2625bdb2346f6586773b20b20977278ac
- https://git.kernel.org/stable/c/a6ff6e7a9dd69364547751db0f626a10a6d628d2
- https://git.kernel.org/stable/c/fe7c3a445d22783d27fe8bd0521a8aab1eb9da65
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.191